ActiScore
← ActiScore
Published evidence

What poor website and email security actually costs

Not our numbers. Every figure below is published by IBM, Verizon or the insurance industry, and linked. We have marked the ones ActiScore can check on a domain in about a second, and left the rest unmarked — because pretending a tool fixes something it does not touch is how a vendor loses a room.

The cost, when it happens

$4.99M

The global average cost of a data breach, across more than 600 organisations breached between March 2025 and February 2026.

IBMCost of a Data Breach Report 2026 · 2026 · figure reported via Help Net Security

247 days

Mean time to identify and contain a breach — eight months in which an attacker is already inside.

IBMCost of a Data Breach Report 2026 · 2026 · figure reported via Help Net Security

62%

Share of breaches involving the human element — someone clicking, trusting or being deceived rather than a firewall being defeated.

VerizonData Breach Investigations Report 2026 · 2026 · figure reported via Abnormal AI

ActiScore checks this: Whether your domain can be impersonated in the emails that deception arrives in — SPF, DKIM and DMARC.

39%

Share of breaches in which stolen credentials appear somewhere in the chain.

VerizonData Breach Investigations Report 2026 · 2026 · figure reported via Abnormal AI

31%

Share of breaches involving exploitation of a known vulnerability — software that had a fix available and had not been updated.

VerizonData Breach Investigations Report 2026 · 2026 · figure reported via Abnormal AI

ActiScore checks this: Whether your server announces its exact software version in its response headers, which tells an attacker which exploit to try first.

26%

Share of known exploited vulnerabilities that were fully remediated in 2025 — down from 38% the year before.

VerizonData Breach Investigations Report 2026 · 2026 · figure reported via Abnormal AI

$50,000

Median loss from a business email compromise, against $6.3 billion in reported losses overall.

VerizonData Breach Investigations Report 2026 · 2026 · figure reported via Keepnet

ActiScore checks this: Whether an attacker can send mail that appears to come from your own domain — the mechanism most invoice fraud starts with.

The cost before anything happens

This is the part most businesses have not caught up with. Cyber insurance underwriting stopped being a questionnaire and became a scan — and the things being scanned are externally visible, which means a broker, a competitor and an attacker can all see them too.

A line item

Email authentication now appears alongside MFA, endpoint detection and backups as a named factor in cyber insurance pricing and coverage availability. Applications ask specifically about DMARC policy, SPF configuration and DKIM key management.

AutoSPFEmail Authentication and Cyber Insurance: How Underwriters Are Pricing DMARC in 2026 · 2026

ActiScore checks this: Your SPF, DKIM and DMARC records, and whether the DMARC policy is enforcing or only watching.

Scanned, not asked

Carriers now run automated scans of an applicant’s external-facing infrastructure during underwriting — checking whether MFA is enforced, whether the email domain publishes DMARC, and whether software is patched.

AutoSPFEmail Authentication and Cyber Insurance 2026 · 2026

ActiScore checks this: The same externally visible posture an underwriter’s scan sees — before they see it.

40–100%

Premium increase reported for businesses that fail the technical audit, alongside coverage exclusions or outright denial into surplus lines at roughly triple the standard rate.

AutoSPFEmail Authentication and Cyber Insurance 2026 · 2026

Travelers v. ICS

A cyber policy was rescinded over the gap between the controls an applicant described and the controls actually running — firewall-only MFA voided a $1 million policy. The claim being genuine did not save it.

Reported in industry coverage of the caseTravelers Property Casualty Co. of America v. International Control Services · 2022, still cited in 2026 underwriting guidance

ActiScore checks this: What is actually running, which is the thing an application form cannot check about itself.

What this does and does not argue

A website audit does not prevent a breach. Nothing on this page claims it does, and a vendor telling you otherwise is selling you something.

What it does is answer, in seconds and without permission, three questions an underwriter now asks and most owners cannot answer about themselves: can anyone send email as this domain, is the certificate about to lapse, and does the server announce which software version to attack. Those are findings, not opinions — and each one is verifiable with a single command, which is why a prospect argues with the fix rather than with the number.

The gap between what a business believes about its own security posture and what is actually published to the internet is the whole conversation. Travelers v. ICS is what that gap costs when it goes untested.

Sources

Every figure on this page is published by someone else and linked. We have no customer case studies yet because we have no customers yet, and an invented one would be the exact thing this product exists to catch.